Privacy policy
We collect what we need to send you a piece, look after you afterwards, and — only with your permission — to stay in touch. We never sell your personal information. You can see, correct, export or delete your data, and withdraw consent, at any time. This notice is written to meet India's DPDP framework, the EU/UK GDPR, and US state privacy laws together.
7.1 Who we are (the data controller / fiduciary)
JEMFYRD is operated by [Legal entity name], [registered address, India], company registration [•], GST [•]. For privacy questions, contact our Grievance Officer / Data Protection contact at privacy@jemfyrd.com.
7.2 What we collect
- Identity and contact details: name, email, phone, billing and shipping addresses;
- Order and account data: purchases, Provenance/engraving personalisation, membership tier, preferences, returns and service history;
- Payment data: processed by our gateways; we receive confirmation and limited details, not full card numbers;
- Communications and content: messages to us, reviews, and any photos or videos you submit ("Seen On Our Muses" / user-generated content);
- Technical and usage data: IP address, device and browser data, and cookie identifiers (Part 8);
- Marketing data: your consents and channel preferences (email, SMS, WhatsApp).
We do not intentionally collect sensitive personal data, biometric, health or government-ID data through the store.
7.3 Why we use it, and our legal basis
- Process and deliver your order; provide warranty, repair and support: performance of a contract.
- Comply with tax, accounting and legal duties: legal obligation.
- Fraud prevention, security, and protecting our rights: legitimate interests.
- Marketing by email / SMS / WhatsApp, abandoned-cart reminders, loyalty & referral: consent, withdrawable at any time.
- Analytics, personalisation and advertising: consent for non-essential cookies; legitimate interests for essential analytics.
7.4 Marketing and your consent
We send marketing only where you have opted in, and you can unsubscribe from any channel at any time via the link in the message or by contacting us. We may send service messages (order, dispatch, warranty) on a non-marketing basis as part of fulfilling your order.
7.5 Who we share it with
We share personal data only with service providers who process it on our instructions under contract, including: our store and hosting platform (Shopify); payment gateways; couriers and fulfilment partners; email/SMS/WhatsApp and reviews platforms; analytics and advertising partners (Part 8); and accounting, tax and fraud-prevention tools. We do not sell personal data, and we do not "share" it for cross-context behavioral advertising except through the advertising cookies you consent to.
7.6 International transfers
Because our partners operate globally, your data may be processed outside your country, including outside India and the EEA. Where we transfer EU/UK data internationally we rely on appropriate safeguards (such as Standard Contractual Clauses); transfers from India follow the DPDP framework and any government-notified restrictions in force at the time.
7.7 How long we keep it
We keep personal data only as long as needed for the purpose collected. Order and tax records are retained for the period required by law (in India, generally up to 8 years for tax/accounting); account and marketing data are kept until you close your account or withdraw consent, then deleted or anonymized. We delete data that is no longer needed.
7.8 Your rights
Subject to your jurisdiction, you may: access a copy of your data; correct it; delete it; restrict or object to processing; port it; and withdraw consent. EU/UK residents may complain to their supervisory authority; Indian residents may approach our Grievance Officer and then the Data Protection Board of India; US-state residents have the rights in Part 12. We verify identity before acting on a request and respond within the statutory timeframe.
7.9 Children
The JEMFYRD store is intended for adults. You must be 18 or over to purchase. We do not direct the store to children or knowingly collect their data; where India's DPDP rules require verifiable parental consent for anyone under 18, we will not process such data without it.
7.10 Security
We use technical and organizational measures — encryption in transit, access controls, vetted processors and breach procedures — to protect your data, and will notify you and the relevant authority of a reportable breach within the timelines the law requires.









